Chris.M
Member
I was discussing this with a KH support crew member last week, actually. I recently decided to implement an SSL certificate on my personal website, and will be doing the same for another project at some point this week. Just for the hell of it, I ran the domain through the Qualys SSL Labs scan. The results were pleasing, with the exception of one little tidbit: the lack of Forward Secrecy support.
Did a bit of research on how one would go about implementing Forward Secrecy, and it was something that I wasn't comfortable with doing. To make a long story short, the configuration that I want to use is apparently not compatible with cPanel servers. (For reference, this is the configuration I'm referring to.) Software compatibility-wise, everything seems to check out... but cPanel blocks the configuration itself. Didn't want to pursue this further at the time as it was really a low-priority matter, but it does intrigue me. Is this something that the folks over at cPanel are actively pursuing? Perhaps there's another way to go about enabling support for Forward Secrecy successfully?
Curious to see if anyone else has stumbled into this. It doesn't seem to be necessary, but more of an added layer of security on top of everything else. And honestly, that's what I'm aiming for.
Chris
Did a bit of research on how one would go about implementing Forward Secrecy, and it was something that I wasn't comfortable with doing. To make a long story short, the configuration that I want to use is apparently not compatible with cPanel servers. (For reference, this is the configuration I'm referring to.) Software compatibility-wise, everything seems to check out... but cPanel blocks the configuration itself. Didn't want to pursue this further at the time as it was really a low-priority matter, but it does intrigue me. Is this something that the folks over at cPanel are actively pursuing? Perhaps there's another way to go about enabling support for Forward Secrecy successfully?
Curious to see if anyone else has stumbled into this. It doesn't seem to be necessary, but more of an added layer of security on top of everything else. And honestly, that's what I'm aiming for.
Chris